Top Exploit Kit Activity Roundup, Spring 2018
ID: c82c5df2-6099-5d48-b29a-c92e5afbdc2f
STIX ID: report--c82c5df2-6099-5d48-b29a-c92e5afbdc2f
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ summarizes exploit kit activity from January–April 2018, identifying RIG as the most active EK (with renewed use of CVE-2018-4878) and GrandSoft and Magnitude also observed; these EKs delivered GandCrab ransomware, cryptocurrency miners, and banking Trojans via malvertising chains and illegal streaming sites, with hits concentrated in the United States, Spain, and Switzerland. The report details infection chains, landing page/redirect patterns, and recommends blocking untrusted third-party scripts, keeping browsers/plugins patched, and leveraging cloud security protections to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
